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[ date of birth 

social 

security account number 

and 




] social security account number|_|were interviewed at their place of 

employment, KEMPER INSURANCE COMPANIES, 1 Kemper Drive, C- 3, Long Grove, 


Illinois, telephone number^ 


After being advised of the identities of the 


interviewing agents an d the nature o f the inte rview, 
following information:! [stated that 


INSURANCE COMPANIES, hereafter referred to as KEMPER 


^provided the 


worked at KEMPER 


"[stated KEMPER does not implement a backgrou nd check on c onsultants because the 


consulting company is supposed to do the background check 
minimal information about individual contract employees.d 


stated KEMPER has 


stated on or about 


04/22/2002 he received a telephone call from representatives of NEAR NORTH INSURANCE 
BROKERAGE (NNIB), hereafter referred to as NNIB, who informed him that someone was 
accessing their network without authorization from an Internet Protocol (IP) address assigned to 
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KEMPER._[stated the individuals f rom NNIB w ith whom he spoke advised they had a 

strong s uspicion of t he identity of the intruder._stated NNIB pr ovided IP ad dresses 

and that_confirmed the IP addresses as belonging to KEMPER. [ stated he 

asked KEMPER's Information Technology (IT) personnel to identify any links to NNIB's 
network from KEMPER's system and the individual most likely t o have been at the specific 

KEMPE R terminals used to access NNIB's network._stated KEMPER's I T personnel 

identified_as the individual assigned to the intru der terminals.[_stated 

KEMPER would have immediately te rminated! but NNIB personnel requested 

KEMPER p ersonnel "keep an eye" on j j to monitor his activities m ore closely. 

_ stated KEMPER personnel became uncomfortable with keeping P j employed. 

n stated personnel from KROEL INC., a for ensic computer investigation firm, were 
hired to handle the investi gation rega rding ! I s activities. ! ! state d staff from 

KROEL who interviewed ! ladvised KEM PER personnel th at ! did not seem to 

appreciate the gravity of the situation f ~ stated ! l advised the KROEL 

personnel that his intrusion into NNIB's network was strictly to satis fy his own curiosity and 
because he still had friends who worked at NNIB. I stated! ! was term inated at 

approximately 6:00 p.m on 04/24/2002 by KROEL personnel and! ~ 

__ stated while employed at 

KEMPER.! ! 

_ was as ked by the interviewing 

agents for the name of KEMPER's Internet service provider. ! I stated he would find out 

who provided Internet access to KEMPER and provide that information to the agents. 



access of NN IB's network were implemented from four computer terminals at KEMPER. 

"I stated three of the termina ls belonged t o KEMPER while the fourth terminal was 
s personal laptop computer. stated t he most activity was perpetuated from 

_s personal laptop. ! I stated_allowed KROEL personnel to review 

his laptop computer prior to b eing termina ted bu t that they d id not find anything that pertained to 

the access of NNI B's network. _stated_declined to allow KROEL personnel 

to retain his laptop_stated the KEMPER network has a banner message that advised 

anyone usin g the system that all property, e-mail messages, etc., are the property of KEMPER. 

stated that employees do not si gn a written document acknowledging this policy. 

_stated KROEL personnel asked ! l i f he did anyth ing t o KEMPER 's network, 

meaning an unauthorized access to KEMPER's system ! ! stated ! l advised that 

he did not do anything to KEMPER's network. ! stated th ere was no evide nce that 

l accessed or hacked their computer network. ! ! stated f ! handwrote a 

letter of ap ology to KEM PER managem ent the same night he was interviewed and eventually 

terminated._Istated ! lad vised he was also going write a letter of apology to 

NNIB regarding t he situation ! I stated the name of KEMPER's contact at KROEL who 

led theF l investig ation is! 

telephone number P provided to the agents a copy of 










handwritten apology letter to KEMPE R regarding the situation, three images of hard 


drives from KEMPER computer terminals used by[ 


to access NNIB's network, a letter 


from KROLL reg arding their imaging of the three hard drives and a CD-ROM containing log 


files. 


stated KEMPER has retained log files from early March 2002 through 


04/20/2002. An FD-597 Receipt of Property was completed and a copy was provided to 

The original FD-597 was placed in a 1-A envelope and secured in the case file. 
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of blrth l I was interviewed at his place of employment, KEM PER INSURAN CE 

COMPANIES, 1 Kemper Drive, Long Grove, Illinois, telephone number . After 

being advised of the identities of the intervie wing agents and the nature of the interview, 

[provided the following information: [vas asked how Internet traffic leaving 

KEMPER'S location and directed to NEAR NORTH INSURANCE BROKERAGE (NNIB) would 
be routed via the lnternet |~ j stated Internet traffic would be routed through KEMPER'S 
server at th e Long Grove, Illinois location and directly to NNIB's server in Chicago, Illinois. 

stated as it pertains to Internet traffic directed to NNIB, he did not observe a KEMPER 
server location from outside Illinois receiving Internet traffic i I stated he observed that 

four work stations at KEMPER were used to access NNIB's e-mail server. | S tated 

three of the locations belonged to KEMPER and one station was assigned to a laptop computer 
belonging to | [ stated when | [ was interviewed b y| 

and KROLL INC. personnel regarding his unauthorized access of NNIB's network. r 
would not let KROLL or KEMPER personnel image the hard drive contained in his laptop. 

stated he and the KROLL personnel had the laptop for approximately 45 mi nutes. 

stated i K emper e-mall account contained no suspicious activity_ 

stated he suspended any dial-in and VPN access belonging to I ~l stated 

I l had no accounts on KEMPER'S mainframe system [ [stated KEMPER has 

three Internet Protocol ranges all beginning with the number "198". stated KEMPER 

implements the intrusion detection software manufactured by ISS called Real Secure. 
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